Mike Dalessio Loofah是Mike Dalessio个人开发者开源的一款HTML文档处理组件。 flavorjones loofah 2.25.2之前版本存在跨站脚本漏洞,该漏洞源于HTML5清理器仅对SVG use和feImage元素上的xlink:href属性应用本地引用限制,而浏览器也接受普通href属性,导致精心构造的SVG可引用外部文档,容易受到跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| flavorjones | loofah | < 2.25.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| flavorjones | loofah | < 2.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73491 | 2.3 LOW | Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace charact |
| CVE-2026-73492 | 2.3 LOW | Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character refere |
No comments yet